{"id":"CVE-2026-23026","title":"dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config()","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config()\n\nFix a memory leak in gpi_peripheral_config() where the original memory\npointed to by gchan->config cou…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 4532f18e4ab36def1f55cd936d0fc002b2ce34c2","Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 694ab1f6f16cb69f7c5ef2452b22ba7b00a3c7c7","Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 6bf4ef078fd11910988889a6c0b3698d2e0c89af","Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 01b1d781394fc9b83015e3a3cd46b17bda842bd8","Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 55a67ba5ac4cebfd54cc8305d4d57a0f1dfe6a85","Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 3f747004bbd641131d9396d87b5d2d3d1e182728","Linux 5.11"],"published":"2026-01-31","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:44:40.750Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-23026","references":[{"url":"https://git.kernel.org/stable/c/4532f18e4ab36def1f55cd936d0fc002b2ce34c2"},{"url":"https://git.kernel.org/stable/c/694ab1f6f16cb69f7c5ef2452b22ba7b00a3c7c7"},{"url":"https://git.kernel.org/stable/c/6bf4ef078fd11910988889a6c0b3698d2e0c89af"},{"url":"https://git.kernel.org/stable/c/01b1d781394fc9b83015e3a3cd46b17bda842bd8"},{"url":"https://git.kernel.org/stable/c/55a67ba5ac4cebfd54cc8305d4d57a0f1dfe6a85"},{"url":"https://git.kernel.org/stable/c/3f747004bbd641131d9396d87b5d2d3d1e182728"}],"tags":["cve.org"],"epss":0.00195,"epssPercentile":0.0944,"ingestedAt":"2026-09-08T15:33:26.994Z","slug":"CVE-2026-23026","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config()\n\nFix a memory leak in gpi_peripheral_config() where the original memory\npointed to by gchan->config could be lost if krealloc() fails.\n\nThe issue occurs when:\n1. gchan->config points to previously allocated memory\n2. krealloc() fails and returns NULL\n3. The function directly assigns NULL to gchan->config, losing the\n   reference to the original memory\n4. The original memory becomes unreachable and cannot be freed\n\nFix this by using a temporary variable to hold the krealloc() result\nand only updating gchan->config when the allocation succeeds.\n\nFound via static analysis and code review.\n\n## Affected\n\n- `Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 4532f18e4ab36def1f55cd936d0fc002b2ce34c2`\n- `Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 694ab1f6f16cb69f7c5ef2452b22ba7b00a3c7c7`\n- `Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 6bf4ef078fd11910988889a6c0b3698d2e0c89af`\n- `Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 01b1d781394fc9b83015e3a3cd46b17bda842bd8`\n- `Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 55a67ba5ac4cebfd54cc8305d4d57a0f1dfe6a85`\n- `Linux >= 5d0c3533a19f48e5e7e73806a3e4b29cd4364130 < 3f747004bbd641131d9396d87b5d2d3d1e182728`\n- `Linux 5.11`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}